Privileged User Management
Privileged User Management (PUM) is how Analog Informatics Corporation (AIC) kits give a person administrator rights only when the work needs them, only for as long as it needs them, and with a record of every step. The industry also calls this Privilege Elevation and Delegation Management (PEDM): endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and auditing of privileged activity.
Elevation works on the local system through the AIC Agent, or by remote control from AIC Server with no agent installed. It works on systems that are always connected, on systems that connect now and then, and on fully air-gapped systems that never reach AIC Server.
Short answers
Does elevation need a network connection?
No. A one-time activation code or a signed grant is checked on the system itself. The Agent needs no connection to AIC Server at the moment of elevation.
Does elevation need an agent?
No. AIC Server can elevate a user on Windows over WinRM and on Linux and Unix over SSH with sudo, with no agent on the target.
How long does elevation last?
For the time the approver set. When the time ends, the kit removes the rights. If the system restarts during the grant, the Agent restores or removes the grant on boot so a restart does not leave rights behind.
Can a person be forced to sign out when elevation ends?
Yes, on Windows and Linux. Forced sign-out on Apple Mac is planned.
Is every elevation recorded?
Yes. Requests, approvals, activation, expiry, and removal are written to the audit trail, the Windows Event Log, and syslog when configured.
How it works
- Request - The user or an administrator asks for elevation.
- From the console or from the Agent on the system
- The request names the system, the person, the reason, and the length of time
- Approve - An approver says yes or no.
- Approval gate with the reason shown
- Optional start delay and a fixed duration
- Deliver - The grant reaches the system by the path that fits the site.
- Pushed or polled signed grant on a connected system
- One-time activation code or challenge and response on an air-gapped system
- Remote job over WinRM or SSH with no agent on the target
- Activate - The system checks the grant and applies it.
- Code or signature checked on the system itself
- Rights applied for the approved time only
- Expire and remove - Rights end on time.
- Automatic removal at the end of the grant
- Restore or remove on boot after a restart
- Optional forced sign-out on Windows and Linux
- Record - Every step is in the audit trail.
Methods of elevation
| Method | How it works | Where it fits |
|---|---|---|
| One-time activation code | AIC Server mints a time-based code for one person, one system, and one time window. The Agent checks the code on the system, with clock drift tolerance, and can require the code to match the exact request | Air-gapped systems, help desk by phone |
| Challenge and response | The system shows a challenge. The approver returns a response. The Agent checks the response on the system | Air-gapped systems where the approver must see the exact system |
| Signed grant | AIC Server signs the grant with an elliptic curve digital signature algorithm (ECDSA) key. The Agent checks the signature before applying it. The grant is pushed to the Agent or picked up when the Agent polls | Connected systems and systems that connect now and then |
| Signed grant package | A signed package carries the grant across the air gap on approved media. The Agent refuses any package it cannot verify | Fully air-gapped systems |
| Agent-local elevation | The Agent applies the grant on the system through a local, protected channel | Any system with the Agent |
| Agentless Windows elevation | AIC Server runs the elevation job over WinRM with PowerShell. No agent on the target | Windows systems where no agent is allowed |
| Agentless Linux and Unix elevation | AIC Server runs the elevation job over SSH with sudo. No agent on the target | Linux and Unix systems where no agent is allowed |
| Agentless Windows file-share elevation | AIC Server runs the job over the Windows file-sharing protocol. Turned off by default | Windows sites that allow this path |
Before a remote job runs, AIC Server can wake a powered-off target so the grant applies and the timer starts on a running system.
What can be granted
Grant
- Membership in a privileged group, such as local Administrators, for a set time
- Specific account rights on Windows
- Durable grants that survive a restart and are restored or removed on boot
- Forced sign-out when the grant ends, on Windows and Linux
- Forced sign-out when the grant ends, on Apple Mac
- A dry run that shows what a grant would change before it runs
- A protected list of accounts and groups that a grant can never change
Application and command control
Capability
- Command restriction in brokered sessions, blocking dangerous commands as they are typed. See Capabilities
- Application broker: measure an application, generate an allow policy for Windows Defender Application Control on Windows, fapolicyd on Linux, and Endpoint Security on Apple Mac, and measure the application again before launch
- Secure Application Launch: start an application with credentials the user never sees
Platforms
Platform
- Windows
- Linux and Unix
- Apple Mac
The same elevation methods work when AIC Server runs on premises, in customer-controlled cloud infrastructure, or inside an air-gapped site. See Air-gapped systems.
Screenshots
Platforms and integrations
Operating systems
All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.